Academy

Module 2 Β· ISO 27001:2022 Implementation πŸ”’

Manish Garg
Manish Garg Associate CISSP Β· RingSafe
April 22, 2026
4 min read

ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). For Indian organisations selling globally, it is often the first formal certification pursued β€” recognized in nearly every market, scoped flexibly, and well-understood. This module covers what ISO 27001 actually requires, the implementation timeline, and the operational realities of getting and keeping certified.

What ISO 27001 actually is

  • An ISMS standard β€” an system for managing security, not a checklist of controls
  • Process-oriented: requires risk assessment, treatment plans, continuous improvement
  • Annex A includes 93 reference controls (down from 114 in the 2013 version) you may select from
  • Certifiable by accredited bodies (BSI, DNV, TUV, BSI India, etc.)
  • 3-year cycle: initial certification audit, surveillance audits years 2 and 3, recertification at year 4

The required documents

ISO 27001 requires specific documented information:

  • ISMS scope statement β€” which parts of the org are in scope
  • Information security policy
  • Risk assessment methodology
  • Risk assessment report
  • Risk treatment plan
  • Statement of Applicability (SoA) β€” for each Annex A control: applicable yes/no, justification, implementation status
  • Internal audit programme
  • Management review records
  • Corrective action records
  • Various procedure documents β€” incident response, access management, change management, etc.

The 2022 control structure

Annex A controls in 27001:2022 are organized into 4 themes (down from 14 in 2013):

  • Organisational (37 controls) β€” policies, roles, supplier relationships, threat intelligence
  • People (8 controls) β€” screening, training, NDA, disciplinary process
  • Physical (14 controls) β€” perimeters, equipment, secure disposal
  • Technological (34 controls) β€” access management, crypto, logging, web filtering, secure coding

11 new controls added in 2022 reflect cloud + supply chain reality: Threat Intelligence (5.7), Information Security for Cloud Services (5.23), ICT Readiness for Business Continuity (5.30), Configuration Management (8.9), Web Filtering (8.23), Secure Coding (8.28), and others.

πŸ” Intermediate Module Β· Basic Tier

Continue reading with Basic tier (β‚Ή499/month)

You've read 27% of this module. Unlock the remaining deep-dive, quiz, and every other Intermediate module.

99+ modulesAll levels up to this tier
20-question quizzesUnlimited retries with explanations
Completion certificatesShareable on LinkedIn
8 more sections locked below